Disaster Recovery: Why "The Cloud" Isn't a Magic Safety Net
First Contact is a managed IT service provider (MSP) based in Whitefield, Manchester, founded in 2001, offering IT support and disaster recovery planning for growing businesses.
Somewhere out there is a business owner who has never once thought about disaster recovery, because they store everything "in the cloud" and assume that word does all the heavy lifting. It doesn't. It's not a vault, a fortress, or a guardian angel. It's someone else's computer, and it will happily save a corrupted file, a ransomware payload, or an accidental "delete all" with exactly the same diligence it saves anything else.
If you've only got a minute: the cloud stores your files, it doesn't protect them from you, from an attacker, or from your provider having a bad day. Disaster recovery is a separate plan with backups, recovery time targets, and a tested process for getting back to work. Most businesses only discover they never had one at the worst possible moment.
The problem: cloud storage isn't a strategy, it's a location
"It's backed up to the cloud" is one of those sentences that sounds like an answer but is actually just a location. Knowing where your data lives tells you nothing about whether you can get it back, how fast, or in what condition.
Cloud sync tools like OneDrive or Google Drive are built to keep files consistent across your devices, not to protect you from disaster. If ransomware encrypts a file on your laptop, sync will cheerfully encrypt the cloud copy too, often before anyone notices. Delete a folder by mistake and, depending on your settings and how long ago it happened, that "safety net" might have already emptied its own recycle bin.
Real disaster recovery answers three questions cloud storage never touches: how much data can you afford to lose, how long can you survive without access to it, and does anyone actually know what to do when the moment arrives.
What we tell clients: build the plan before you need it
A proper disaster recovery setup has layers, because no single layer survives every kind of disaster.
Backups that are actually separate from your live data. Not a synced folder, a genuine backup with version history, stored somewhere an attacker in your network can't also reach and encrypt.
A recovery time objective. Not "as fast as possible", an actual number. Four hours? Two days? The honest answer shapes everything else about the plan and the budget.
A recovery point objective. How much work can you afford to redo. If your backups run nightly and disaster strikes at 4pm, that's a full day gone. For some businesses that's a shrug. For others it's a genuine crisis.
A tested restore process. A backup nobody has ever restored from is a hypothesis, not a plan. We test client restores on a schedule, because the first time you find out a backup doesn't work should never be during the emergency.
Key takeaway
The cloud is brilliant at what it does. It is not, on its own, a disaster recovery plan, and treating it like one is how businesses find out the hard way that "it's backed up" and "we can get it back" are two very different sentences. The fix isn't complicated or dramatic: know your numbers, separate your backups from your live systems, and actually test the thing before you need it. That's the whole plan, and it's cheaper than the alternative every single time.
FAQs
Is cloud storage the same as a backup?
No. Cloud storage like OneDrive or Google Drive syncs your files across devices, but it also syncs deletions, corruption, and ransomware encryption. A true backup is a separate, versioned copy that isn't automatically overwritten when your live files change.
What is a recovery time objective (RTO)?
It's the maximum amount of time a business can be without a system or dataset before the disruption causes serious harm. It's a business decision as much as a technical one, and it directly shapes what kind of backup and recovery setup makes sense.
What is a recovery point objective (RPO)?
It's how much data loss, measured in time, is acceptable. If backups run every 24 hours and something fails just before the next backup, the RPO determines how much work is lost, not just how much data.
Can ransomware infect cloud backups?
If a backup is just a synced copy of live files, yes, it can be encrypted right alongside the original. Backups need to be isolated and versioned so a clean copy always exists to roll back to.
How often should a disaster recovery plan be tested?
At minimum annually, though most growing businesses benefit from testing after any significant change to systems, staff, or infrastructure. An untested plan is an assumption, not a safeguard.